New Worm Searches Google For Victims

CYBERSPACE — A new Internet worm discovered today uses popular search engine Google to find potential victims and has caused what antivirus firm Kaspersky calls an “epidemic.”

Net-Worm.Perl.Santy.a, which targets the phpBB online bulletin board software, apparently searches Google for “viewfiles.php” which reveals vulnerable versions of phpBB, then launches an attack on the site.

“Santy.a is something of a novelty,” Kaspersky said. “It creates a specially formulated Google search request which results in a list of sites running vulnerable versions of phpBB.”

Once the virus has located its targets and successfully infected a site, it searches for and overwrites files with .asp, .htm, .jsp, .php, .phtm, and .shtm extensions. In their place, the worm places files which contain the text, “This site is defaced!!! NeverEverNoSanity WebWorm generation.”

Original reports suggested that the worm was exploiting one of the major PHP vulnerabilities announced last week by the open-source group that distributes the programming language, but the Internet Storm Center recently stated that the exploit lies in the “highlight” feature in versions of phpBB earlier than 2.0.11.

The “highlight” exploit centers around an SQL injection bug that allows attackers to arbitrarily execute code.

A search using Microsoft’s search engine for text strings contained in infected files turned up approximately 40,000 sites at 11 a.m. on Tuesday. The same search conducted at 12:30 p.m. revealed 133,780 hits.

“Santy.a is spreading rapidly and has caused an epidemic,” Kaspersky stated. “However, this does not directly affect users. Although the worm infects websites, it does not infect computers used to view those sites.”

Copyright © 2025 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

FSC 2026/2027 Board Members Announced

The Free Speech Coalition (FSC) has announced the results of its 2026/2027 Board of Directors election.

Report: AVS Group Beefs Up AV After $1.3 Million Fine

Adult content provider AVS Group has begun to institute robust age checks on some of its websites after U.K. media regulator Ofcom last week imposed a penalty of approximately $1.3 million for noncompliance with Online Safety Act regulations, the BBC is reporting.

FSC: Federal Report Confirms Unfair Banking Discrimination Against Adult Industry

The Free Speech Coalition (FSC) today announced that a federal report on debanking has concluded that several U.S. banks engaged in discriminatory banking practices against members of the adult industry.

Pineapple Support Names Natalie Pereira Executive Assistant

Pineapple Support has appointed Natalie Pereira as its new executive assistant.

AEBN Publishes Popular Searches by Country for October, November

AEBN has released the list of popular searches from its straight and gay theaters by country in October and November.

FSC Summit Event Schedule Announced

Free Speech Coalition (FSC) has revealed its slate of networking events and symposiums for its annual summit, set for January 15 during XBIZ 2026.

Pornhub Releases 2025 'Year in Review' Report

Pornhub has released its “Year in Review Insights” report for 2025, the 12th edition of the site’s annual statistics, data analysis, and infographic initiative.

Washington AV Bill Jumps on 'Health Warning' Bandwagon

A new age verification bill in the Washington state legislature would require adult sites to post notices warning users of alleged health risks, despite a previous federal court ruling against such requirements.

BranditScan Launches '25 Days of Christmas' Promo

BranditScan has launched its 25 Days of Christmas promotion.

MelRose Michaels Named Host of Online Industry Edition of XBIZ Honors

Performer and entrepreneur MelRose Michaels will MC the online industry edition of the 2026 XBIZ Honors, set for Wednesday, Jan. 14, at the Kimpton Everly Hotel in Hollywood.

Show More